PT-2025-51930 · Churchcrm · Churchcrm
Uartu0
·
Published
2025-12-17
·
Updated
2025-12-20
·
CVE-2025-68112
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
ChurchCRM versions prior to 6.5.3
Description
ChurchCRM is an open-source church management system. A SQL injection flaw exists in the Event Attendee Editor. This allows authenticated users to execute arbitrary SQL commands, potentially leading to complete database compromise, administrative credential theft, and system takeover. Attackers could extract sensitive member data, authentication credentials, and financial information. The vulnerable component is the Event Attendee Editor. SQL injection is a code injection technique used to attack data-driven applications, in which malicious SQL statements are inserted into an entry field for execution.
Recommendations
Upgrade to version 6.5.3 to address this issue.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Churchcrm